WindowsEventLogDataSource Class

Definition of which Windows Event Log events will be collected and how they will be collected. Only collected from Windows machines.

Constructor

WindowsEventLogDataSource(*, streams: List[str | _models.KnownWindowsEventLogDataSourceStreams] | None = None, x_path_queries: List[str] | None = None, transform_kql: str | None = None, name: str | None = None, **kwargs: Any)

Keyword-Only Parameters

Name Description
streams

List of streams that this data source will be sent to. A stream indicates what schema will be used for this data and usually what table in Log Analytics the data will be sent to.

Default value: None
x_path_queries

A list of Windows Event Log queries in XPATH format.

Default value: None
transform_kql
str

The KQL query to transform the data source.

Default value: None
name
str

A friendly name for the data source. This name should be unique across all data sources (regardless of type) within the data collection rule.

Default value: None

Variables

Name Description
streams

List of streams that this data source will be sent to. A stream indicates what schema will be used for this data and usually what table in Log Analytics the data will be sent to.

x_path_queries

A list of Windows Event Log queries in XPATH format.

transform_kql
str

The KQL query to transform the data source.

name
str

A friendly name for the data source. This name should be unique across all data sources (regardless of type) within the data collection rule.